Incorrect permission assignment for critical resource in Siemens products - CVE-2021-31894
Published: July 14, 2021
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to incorrect permission assignment for critical resource. A local user can change the content of certain metafiles and subsequently manipulate parameters or the behavior of devices that would be later configured by the affected software.
Affected software
SIMATIC PDM
SIMATIC STEP 7
SINAMICS STARTER